Patient History De-Identification with anonym.plus

Clear IDs from medical, social, and family history while the story stays.

Patient-history de-identification is the removal of IDs from the medical, social, and family parts of a file. It meets HIPAA Safe Harbor (45 CFR §164.514(b)). anonym.plus runs locally, with care for the social and family parts that hold the most indirect clues.

When this applies

A full history is gold for teaching and research. But the social part (job, habits, place) and the family part (named kin, their illness) are dense with indirect clues that must go.

How anonym.plus handles it

  1. Load the file into anonym.plus on your device.
  2. It scans the medical, social, and family parts.
  3. Named kin, jobs, and places get flagged as indirect clues.
  4. Swap them so the story still flows.
  5. Save the clean history on your device.

What you need to provide

PHI entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONpatient & kin → [NAME]
LocationLOCATIONminer, Essen → [LOCATION]
DatesDATE_TIMEsmoker since 1998 → [DATE]
RelativesPERSONfather, dx 2010 → [RELATIVE]
Record IDsMEDICAL_RECORD_NUMBERMRN → [MRN]
IdentifiersNATIONAL_IDnational ID → [ID]

Compliance achieved

Anonymize patient histories offline — see plans & start free →

Limitations & cautions

The social and family parts are the hardest to fully clear. A rare job in a small town, or a named relative's rare illness, can re-identify after direct IDs go. Review these parts and use Expert Determination for odd cases.

Frequently asked questions

Why are the social and family parts riskier?

They hold indirect clues — jobs, places, named kin, and their illness — that can point to one person with no direct name or number.

Are the kin details removed too?

Yes. Named kin and their clues are flagged and swapped, since they are PHI inside the file.

Can the history still serve teaching?

Yes. The medical story stays. Only the identifying detail changes.